CVE Tools

LiteLLM Vulnerability Chain Lets Low-Privilege Users Take Over AI Gateway Servers

The Hacker NewsBy The Hacker News

PoC publicLiteLLM

Our summary

Researchers at Obsidian Security report a multi-step vulnerability chain in LiteLLM that can allow a default low-privilege account to escalate to full proxy admin and achieve code execution. The affected issues are tracked as CVE-2026-47101, CVE-2026-47102, and CVE-2026-40217; together they can bypass authorization, elevate privileges, and escape the Custom Code Guardrail’s sandbox. Because LiteLLM sits in the middle of AI requests, a takeover can expose provider keys and sensitive traffic and can also let attackers tamper with prompts/responses processed by downstream agents. BerriAI’s fix is included starting with LiteLLM v1.83.14-stable—upgrade to that release or later to mitigate.

Read at The Hacker News

The Hacker News publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store